'Zombie Card' Attack Brings Expired Visa Contactless Cards Back to Life

UMass Amherst researchers show how to rewrite the expiry date a payment terminal sees, letting dead cards buy real goods.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A contactless payment terminal with a card being held near it, with the terminal's display screen visible showing an expiry date, and laboratory testing equipme
Share

Key points

  • Researchers at the University of Massachusetts Amherst built an attack, dubbed Zombie Card, that lets expired Visa contactless cards make real purchases in shops.
  • The trick rewrites the expiration date a payment terminal reads over NFC (near-field communication, the short-range wireless link used for tap-to-pay), without cracking any of the card's cryptography.
  • Brief physical access to the target card is required, so this isn't a remote attack on the payment network.
  • Visa's contactless standard, not any individual card's chip, is where the weakness sits, meaning every bank issuing on that standard is exposed until Visa changes how expiry is checked.
  • No customer-side patch exists yet; destroying expired cards promptly is the only practical step available to shoppers.

Academics have found a way to make a dead credit card spend money again.

A team at the University of Massachusetts Amherst has demonstrated an attack they call Zombie Card, which revives expired Visa contactless cards and uses them for genuine in-store purchases. It was first reported by The Hacker News.

The method doesn't break the card's cryptography, meaning it doesn't defeat the mathematical locks that normally protect card data. What it targets is simpler: the expiration date a shop's payment terminal reads from the card over NFC. By rewriting the date the terminal sees, the researchers convinced point-of-sale devices that a long-dead card was still valid, and the card completed a normal contactless payment.

How does the attack actually work?

When a shopper taps a Visa contactless card on a terminal, the two devices exchange a short conversation over NFC. Inside that exchange sits the card's expiry date, sent in a field the terminal trusts without a separate cryptographic check. The UMass team showed this field can be altered on the fly, while the rest of the transaction, including the cryptographically signed parts, still validates. A terminal that sees an in-date card approves the sale.

The flaw is in how Visa's contactless specification handles the expiry field, not in any single bank's implementation. That's what the researchers mean when they call it a protocol-level issue.

What does an attacker need?

Physical access to the card, at least briefly. Zombie Card isn't a way to clone cards from across a room or drain accounts over the internet. The scenario the researchers describe involves a criminal obtaining an expired card from discarded post or a stolen wallet, then using it with their rig at a checkout.

That limits scale considerably. Even so, it means every expired Visa card sitting in a drawer or recycling bin is, in theory, still spendable. We covered the mechanics of physical card-skimming hardware on 15 August 2026; this attack requires no hardware planted on the terminal at all, which changes the threat model for retailers accustomed to checking for skimmers.

Should ordinary shoppers worry?

Probably not day to day, but destroy expired cards properly. Cut through the chip and the magnetic stripe before throwing the card away. Don't assume an expiry date printed on the card's face means the chip inside has stopped working.

If you spot charges on a closed or expired card account, report them to your bank as you would any fraud. Under UK and EU rules, unauthorised card transactions are generally refundable.

Detail What the researchers say
Attack name Zombie Card
Discovered by University of Massachusetts Amherst
Card brand affected Visa contactless
Access needed Physical possession of the expired card
Cryptography broken? No
Fix location Visa's contactless specification

Where does the fix have to come from?

From Visa, and from the terminals. Individual banks can't patch this alone by reissuing plastic, because the weakness sits in how the expiry date is trusted during a tap. Visa would need to update the specification so terminals verify expiry against a signed value, and terminal vendors would then need to roll that change across millions of devices in shops worldwide.

That's a slow pipeline. Worth watching: Visa spent $2.4 billion in August to acquire fraud-detection firm BioCatch, a purchase built around catching anomalous behaviour before money moves. Whether that investment extends to fixing specification-level gaps like this one is the real question.

© 2026 Threat Vectr